Exposed Bitcoin Wallets Face Critical Security Risk

A critical flaw in Alby Hub allowed attackers to steal funds from wallets exposed to the internet, affecting users who ran older versions.
Bitcoin wallet provider Alby has disclosed a critical security flaw in its Alby Hub software that allowed attackers to take control of wallets and drain their funds. The vulnerability specifically targeted instances where users had configured the software to be accessible from the public internet, a setup that the company now advises against.
According to reporting by The Hacker News, the flaw affected versions 1.7.0 through 1.18.5, all released before August 2025. Alby confirmed that at least one user was impacted, though the company did not specify if funds were lost. The issue has been patched in version 1.19.0 and later, with the current release being 1.24.0.
The risk of public exposure
Alby Hub is designed to be a self-hosted solution, meaning users run the software on their own hardware to control their assets. However, the vulnerability only manifested when the management interface was reachable from outside the user's private network. If the software was kept strictly local, the flaw did not pose a threat.
The company has urged users on older versions to immediately restrict external access to the wallet's web interface. For those using containerized setups like Docker, this means binding the service to the local loopback address rather than all network interfaces. On cloud servers, firewall rules must be adjusted to block public traffic to the specific port used by the hub.
Documentation errors guided users
The situation was complicated by misleading official documentation. Until recently, Alby's setup guides for cloud providers described configurations that left the hub open to the internet. One guide explicitly recommended keeping the public server address active so users could access the wallet via a browser.
A documentation update merged on September 7 corrected these errors, noting that previous guides incorrectly stated the server ran on localhost when it actually listened on all available network connections. This change also updated the default Docker configuration to restrict access to the local machine only, reducing the likelihood of accidental exposure for new installations.
Immediate steps for users
Alby recommends that all users verify their current version and update to 1.24.0 regardless of their exposure status. For those who ran an affected version and had internet access enabled, the company advises changing the wallet's unlock password after updating. This step is intended to invalidate any potential access an attacker may have established before the patch was applied.
The company has not yet published technical details on the specific mechanism of the exploit, citing responsible disclosure practices. However, the advice to change credentials suggests that the vulnerability may have allowed unauthorized session persistence or direct control over the wallet interface. Users with confirmed exposure should also contact Alby's security team for further guidance.






